SharePoint RCE (CVE-2026-45659) Is Being Actively Exploited -- Patch Now
Dr. Abeer Alshammari · Published 7/29/2026
Executive View
On-premises SharePoint servers are being actively exploited via a remote code execution flaw (CVSS 8.8) that requires only low-privilege authenticated access. A fix has existed since May 2026. Any organization still running unpatched on-premises SharePoint Server, Subscription Edition, 2019, or Enterprise 2016 should treat this as an immediate patching action, not a scheduling decision. Decision required: confirm patch status today; if unpatched, isolate or patch within 24 hours.
Vulnerability Intelligence
- CVE
- CVE-2026-45659
- CVSS
- 8.8
- Affected product
- Microsoft SharePoint Server (Subscription Edition, 2019, Enterprise Server 2016) -- SharePoint Online is not affected
- Exploit status
- Actively exploited
- CISA KEV listed
- Yes
- Patch status
- Patch available since May 2026; apply immediately if not already applied
- Vendor advisory
- Vendor advisory
CyberAbeer's own prioritization guidance, based on severity, known exploitation, and exposure -- not an official vendor or CISA rating.
Sources last checked 7/29/2026
CISA confirmed active exploitation and added this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog on July 1, 2026. A patch has been available since May 2026.
What happened
CISA added CVE-2026-45659, a Microsoft SharePoint Server deserialization-of-untrusted-data remote code execution vulnerability, to its KEV catalog on July 1, 2026, citing evidence of active exploitation. Microsoft shipped a patch in May 2026 but did not publicly disclose the vulnerability until May 21. Federal Civilian Executive Branch agencies were given until July 4, 2026 to remediate.
Why it matters
The flaw does not require administrator privileges: an authenticated attacker with only Site Member-level access can trigger remote code execution in a low-complexity attack that needs no user interaction. Combined with a roughly six-week gap between patch availability and public disclosure, many organizations plausibly have not yet applied it.
Who is affected
Organizations running on-premises SharePoint Server Subscription Edition, SharePoint Server 2019, or SharePoint Enterprise Server 2016. SharePoint Online (Microsoft-managed) is not affected -- this is specifically a self-hosted patching problem.
Technical impact
| Field | Detail |
|---|---|
| CVE | CVE-2026-45659 |
| CVSS | 8.8 |
| Vulnerability type | Deserialization of untrusted data -> remote code execution |
| Privileges required | Low (authenticated Site Member) |
| User interaction | None |
| CISA KEV | Added July 1, 2026 |
| Patch availability | May 2026 (disclosed May 21, 2026) |
Governance impact
This is a patch-management control failure pattern, not a novel attack technique: the fix existed for weeks before exploitation was confirmed. Organizations should treat the gap between "patch available" and "patch applied" as a tracked metric with an owner, not an assumption.
What security teams should do
- Confirm patch status on every on-premises SharePoint Server instance today
- If unpatched, apply the May 2026 update immediately or isolate the server from untrusted networks
- Review SharePoint server logs for indicators of exploitation predating patching
- Confirm SharePoint Online is correctly excluded from this exposure in your asset inventory
What executives should know
A working fix has existed for months. The organizational risk now is entirely about how quickly known patches get applied to internet-facing, business-critical systems -- a process and accountability question, not a technology gap.
The decision this forces is not "should we patch" -- it is "who owns confirming patch status on every SharePoint instance, and by when." If that owner and deadline do not already exist, this is the control gap to close, independent of this specific CVE.
On-premises SharePoint remains widely deployed across GCC government and enterprise environments, including in sectors with lower cloud-migration rates. Confirm exposure specifically for on-premises deployments rather than assuming Microsoft 365/SharePoint Online coverage applies.